Vulnerabilities (CVE)

Filtered by vendor Redaxo Subscribe
Filtered by product Redaxo
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2006-2845 1 Redaxo 1 Redaxo 2018-10-18 7.5 HIGH N/A
PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PATH] parameter to image_resize/pages/index.inc.php.
CVE-2012-3869 1 Redaxo 1 Redaxo 2012-08-14 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in include/classes/class.rex_list.inc.php in REDAXO 4.3.x and 4.4 allows remote attackers to inject arbitrary web script or HTML via the subpage parameter to index.php.